Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43999
Total
3569
Critical
13202
High
13005
Medium
CVE ID Severity Score Description Published
CVE-2026-47626 HIGH 8.2 NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit … Aug 25, 2026
CVE-2026-47624 MEDIUM 6.0 NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability … Aug 25, 2026
CVE-2026-24263 HIGH 8.2 NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful … Aug 25, 2026
CVE-2026-24262 HIGH 8.2 NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit … Aug 25, 2026
CVE-2026-24225 MEDIUM 6.0 NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit … Aug 25, 2026
CVE-2026-24170 HIGH 8.8 NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP … Aug 25, 2026
CVE-2026-24169 HIGH 8.0 NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially … Aug 25, 2026
CVE-2026-24168 MEDIUM 6.8 NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API … Aug 25, 2026
CVE-2026-24167 MEDIUM 6.8 NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A … Aug 25, 2026
CVE-2026-24166 MEDIUM 5.1 NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful … Aug 25, 2026
CVE-2026-19913 HIGH 7.5 The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter … Aug 25, 2026
CVE-2026-19912 UNKNOWN The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php … Aug 25, 2026
CVE-2026-18445 MEDIUM 6.6 There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code … Aug 25, 2026
CVE-2026-18444 MEDIUM 6.6 There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure … Aug 25, 2026
CVE-2026-16234 HIGH 7.8 There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … Aug 25, 2026
CVE-2026-16233 HIGH 7.8 There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … Aug 25, 2026
CVE-2026-13478 MEDIUM 5.5 The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) … Aug 25, 2026
CVE-2026-13217 MEDIUM 5.9 The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code … Aug 25, 2026
CVE-2026-13216 MEDIUM 6.1 The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI … Aug 25, 2026
CVE-2026-79785 MEDIUM 5.9 X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain … Aug 25, 2026
CVE-2026-79784 HIGH 8.8 Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the … Aug 25, 2026
CVE-2026-79783 LOW 3.6 rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on … Aug 25, 2026
CVE-2026-79782 LOW 3.1 rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can … Aug 25, 2026
CVE-2026-79781 MEDIUM 6.5 rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 … Aug 25, 2026
CVE-2026-79780 MEDIUM 5.3 rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme … Aug 25, 2026